LATAM Infrastructure Hit by Fortinet and Ivanti Exploits
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-42475 | Unauthenticated Heap Overflow in Fortinet FortiOS/FortiProxy SSL-VPN (Critical RCE) CVE-2022-42475 is a critical (CVSS 9.8) heap-based buffer overflow in the SSL-VPN service of Fortinet FortiOS and FortiProxy. A remote, unauthenticated attacker can trigger it by sending specifically crafted requests to an exposed SSL-VPN interface, with no user interaction or credentials required. Successful exploitation yields arbitrary code or command execution on the appliance, giving attackers a foothold on the perimeter device from which they can pivot into internal networks. Any organization running the listed FortiOS (6.0 through 7.2) or FortiProxy (7.0/7.2) versions with SSL-VPN enabled is affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, has near-certain exploitation probability (EPSS 99.5%), and has been used in targeted government attacks and a Chinese-nexus espionage campaign that compromised over 20,000 systems, with attackers also noted to retain access even after patching. Do: Upgrade FortiOS and FortiProxy to fixed releases per Fortinet advisory FG-IR-22-398 (any version beyond the listed affected ranges), and reboot the appliance after patching to clear lingering SSL-VPN sessions since attackers have been observed retaining access post-patch. Check for indicators of compromise such as unknown local accounts, unexpected processes, and anomalous historical logins, and rotate SSL-VPN credentials if compromise is suspected. If SSL-VPN is not required, disable it or restrict exposure to trusted sources until patched. | 9.8 | 99% | KEV ransomware PoC |
| masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL-VPN endpoints (well over 100,000; 20,000+ confirmed victims in a single campaign) | |
| CVE-2024-21887 +1 in the same advisory: …46805 | Command Injection RCE in Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available. Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories. | 9.1 group max | 100% | KEV ransomware PoC |
| largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher) | |
| CVE-2024-21762 | Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted. Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority. | 9.8 | 84% | KEV ransomware |
| mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans) | |
| CVE-2025-0282 | Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known. Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin. | 9.0 | 100% | KEV ransomware PoC ×3 |
| largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways) |
Full article440 words · extracted from infosecurity-magazine.com · click to collapse
A coordinated campaign against government and financial targets across Latin America has been laid bare by the attackers' own mistake, after they left a staging server exposed online.
New analysis from CloudSEK detailed the operation, which it named Operation Escaneo, after researchers found an open directory on the group's server in early 2026 and mapped its toolkit from the artifacts left behind.
The campaign hit critical infrastructure across Mexico, with lesser activity in Ecuador and Portugal, spanning government, tax authorities, utilities, transport, telecoms and banks.
CloudSEK said it confirmed beacons from at least five victims and large-scale data theft.
Breaking In Through the Perimeter
Entry came mainly through internet-facing security appliances. The group kept tuned exploits for Fortinet FortiOS SSL-VPN flaws, including CVE-2022-42475 and CVE-2024-21762, and Ivanti Connect Secure flaws CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282, adapting public proof-of-concept (PoC) code so it would not crash the target.
Its reach went well beyond perimeter gear, with exploits for Apache Tomcat's GhostCat flaw, the Windows bugs EternalBlue and Zerologon and Log4Shell.
All of it was fed by a custom reconnaissance engine the group calls Kimera, which CloudSEK said scanned and triaged targets at high speed, then handed them straight to the exploitation stage.
Tunnels, Routers and Stolen Data
To stay connected, the group layered its access. Neo-reGeorg webshells gave encrypted footholds on web servers, Chisel reverse tunnels carried traffic over HTTP and a compromised Cisco router was fitted with a GRE tunnel pointing back to the attackers, a network-level channel invisible to host-based defenses.
Chisel logs alone recorded 3,708 sessions over a 13-day window.
Inside victim networks, the attackers reached SAP and Oracle systems to run commands and pulled out a large volume of sensitive data, including:
-
More than 1.3 million personal records from one transport provider
-
A 407MB map of a victim's Active Directory
-
SSL private keys, streamed out live from a database server
-
SAP service-account hashes and browser-stored passwords
A Suspected Hacktivist Link
CloudSEK attributed the campaign, with medium confidence, to a group it calls Mexican Mafia, or Pancho Villa, which spent 2024 claiming breaches against Mexican government, judicial and energy targets, sometimes casting the hacks as protest.
The firm hedged the link, noting some of the group's past claims have been disputed by the organizations named.
Regardless of the link, CloudSEK urged Latin American organizations to patch perimeter appliances first, singling out the Fortinet and Ivanti flaws and to watch for the operation's quieter tells.
These include GRE tunnels reaching external addresses, Chisel's TCP-over-HTTP traffic and unexpected commands running through SAP and Oracle.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/operation-escaneo-cloudsek-latam/